I'm talking about the firewall which is network handling only.
Most host firewalls only block incoming traffic.
All you have to do is get all mining data by making outgoing web connections to some random proxy, which can optionally have a domain to look more legit.
Firewall won't care, and unless you're pouring over the logs or looking at active connections, you won't find it either.
Since it's mining software, the fastest giveaway would be high usage or running an anti-virus to find sketchy executables.
I'm assuming OP is on windows which means the installer asked for admin perms to install to program files which is a really easy way to hide your mining executable assuming it hasn't been fingerprinted by popular anti virus yet.